<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Workspace in Security</title>
    <link>https://community.splunk.com/t5/Security/Google-Workspace/m-p/675647#M17574</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi there,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The key is finding those Workspace login logs.&lt;/SPAN&gt;&lt;SPAN&gt; While the add-on and apps might be installed,&lt;/SPAN&gt;&lt;SPAN&gt; there could be a filtering or indexing issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here's a quick rundown:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Check the filter:&lt;/STRONG&gt;&lt;SPAN&gt; Did you configure any filters that might exclude login events?&lt;/SPAN&gt;&lt;SPAN&gt; Double-check your inputs.&lt;/SPAN&gt;&lt;SPAN&gt;conf settings specifically.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Look for indexing errors:&lt;/STRONG&gt;&lt;SPAN&gt; Splunk logs might reveal indexing errors related to Workspace data.&lt;/SPAN&gt;&lt;SPAN&gt; Check &lt;/SPAN&gt;splunkd.log&lt;SPAN&gt; and &lt;/SPAN&gt;python.log&lt;SPAN&gt; for clues.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Search smarter:&lt;/STRONG&gt;&lt;SPAN&gt; The provided search might not translate perfectly to Workspace.&lt;/SPAN&gt;&lt;SPAN&gt; Try broader terms like "google login" or "workspace access" and adjust from there.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;If you're still stuck,&lt;/SPAN&gt;&lt;SPAN&gt; I recommend searching Splunkbase forums or reaching out to Splunk or Google Workspace support directly.&lt;/SPAN&gt;&lt;SPAN&gt; They've seen it all and can offer specific guidance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remember,&lt;/SPAN&gt;&lt;SPAN&gt; hunting invaders is like being a detective – persistence and resourcefulness are key!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;~ If the reply helps, a Karma upvote would be appreciated&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jan 2024 10:14:45 GMT</pubDate>
    <dc:creator>datadevops</dc:creator>
    <dc:date>2024-01-28T10:14:45Z</dc:date>
    <item>
      <title>Google Workspace</title>
      <link>https://community.splunk.com/t5/Security/Google-Workspace/m-p/675526#M17572</link>
      <description>&lt;P&gt;Hello Every Body.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm starting this question be couse i'm traying to genrate detections for goole workspace invader as that post about 365.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-blue-team-s-guide-to-initial-access-vectors.html" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/blog/security/hunting-m365-invaders-blue-team-s-guide-to-initial-access-vectors.html&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i can not find google work space&amp;nbsp; login logs in actual ingest. We installed&amp;nbsp; the ad-don and newest apps abalaible in the splunkbase and could not find it.&lt;/P&gt;&lt;P&gt;surfin into the splunk web we could't fund an euivalent searchs as the link attached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some bady had the same problem?&amp;nbsp; how can I solved it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:57:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Google-Workspace/m-p/675526#M17572</guid>
      <dc:creator>cbarrios</dc:creator>
      <dc:date>2024-01-26T14:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace</title>
      <link>https://community.splunk.com/t5/Security/Google-Workspace/m-p/675647#M17574</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi there,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The key is finding those Workspace login logs.&lt;/SPAN&gt;&lt;SPAN&gt; While the add-on and apps might be installed,&lt;/SPAN&gt;&lt;SPAN&gt; there could be a filtering or indexing issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here's a quick rundown:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Check the filter:&lt;/STRONG&gt;&lt;SPAN&gt; Did you configure any filters that might exclude login events?&lt;/SPAN&gt;&lt;SPAN&gt; Double-check your inputs.&lt;/SPAN&gt;&lt;SPAN&gt;conf settings specifically.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Look for indexing errors:&lt;/STRONG&gt;&lt;SPAN&gt; Splunk logs might reveal indexing errors related to Workspace data.&lt;/SPAN&gt;&lt;SPAN&gt; Check &lt;/SPAN&gt;splunkd.log&lt;SPAN&gt; and &lt;/SPAN&gt;python.log&lt;SPAN&gt; for clues.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Search smarter:&lt;/STRONG&gt;&lt;SPAN&gt; The provided search might not translate perfectly to Workspace.&lt;/SPAN&gt;&lt;SPAN&gt; Try broader terms like "google login" or "workspace access" and adjust from there.&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;If you're still stuck,&lt;/SPAN&gt;&lt;SPAN&gt; I recommend searching Splunkbase forums or reaching out to Splunk or Google Workspace support directly.&lt;/SPAN&gt;&lt;SPAN&gt; They've seen it all and can offer specific guidance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remember,&lt;/SPAN&gt;&lt;SPAN&gt; hunting invaders is like being a detective – persistence and resourcefulness are key!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;~ If the reply helps, a Karma upvote would be appreciated&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 10:14:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Google-Workspace/m-p/675647#M17574</guid>
      <dc:creator>datadevops</dc:creator>
      <dc:date>2024-01-28T10:14:45Z</dc:date>
    </item>
  </channel>
</rss>

